pypi
Malicious secmeasure @0.1.2
Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 12:32 PM UTC
OSV ID
MAL-2025-47452
Ecosystem
pypi
Summary
This package installs the SilentSync remote access trojan and allows remote code execution and data exfiltration. Windows machines are targetted by this malicious package.
Source: google-open-source-security (f566db2e1359b455ca36524d9c066854754e71ac92deca9706f69d3d71cc8414)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.